
ISO/IEC 42001 certifies that you have a system for managing AI risk — not that your model is safe. What the standard actually requires, what a certificate is worth, and why it does not make you EU AI Act compliant.
ISO/IEC 42001:2023 is a management system standard for artificial intelligence. It was published in December 2023 by ISO/IEC JTC 1, Subcommittee SC 42, the joint technical committee responsible for AI standards, and it is the first AI management system standard you can be certified against.
"Management system standard" is the load-bearing phrase. It puts 42001 in the same family as ISO 9001 (quality), ISO 14001 (environment), and ISO/IEC 27001 (information security). These standards do not certify a product. They certify that an organisation has a repeatable, documented, audited way of managing a particular class of risk.
So ISO 42001 does not certify that your model is accurate, fair, safe, or free of hallucination. It certifies that you have a system for deciding what "acceptable" means for your AI, checking whether you are meeting it, and doing something when you are not. That distinction matters when a buyer waves a certificate at you as proof of model quality, and it matters even more when you are the one waving it.
The scope is deliberately wide. The standard applies to any organisation, regardless of size, type and nature, that provides or uses products or services that utilise AI systems. You do not have to train models to be in scope. A company whose entire AI footprint is a vendor chatbot and three Copilot licences is squarely inside it.
The document has two halves, and people who have implemented ISO 27001 will recognise the shape immediately.
Clauses 4 to 10 are the management system requirements, using the harmonized structure — identical clause numbers, titles, text and core definitions shared across management system standards. In order: context of the organisation, leadership, planning, support, operation, performance evaluation, improvement. Plan-Do-Check-Act, in other words. If you already run a certified ISMS, this half is mostly a scope extension rather than a new build.
Annex A is the reference set of AI-specific controls, and Annex B is the implementation guidance for them. One detail that trips people up: in ISO/IEC 42001, both Annex A and Annex B are normative. Annex B is not optional commentary — it is roughly 25 pages of the standard against which auditors will form a view of whether your controls are real. Annex C (potential AI-related organisational objectives and risk sources) and Annex D (use of the AI management system across domains or sectors) are informative.
The Annex A controls are grouped under objectives covering AI policy, internal organisation, resources, impact assessment, the AI system lifecycle, data, information for interested parties, responsible use, and third-party relationships. A note on the control count: published summaries variously report 38, 39, and 42 controls. The most commonly cited figure is 38 controls across nine objectives (A.2–A.10), and it is the one I would use — but Annex A sits behind the paywall, the freely available preview stops at clause 4, and I have not counted them in the licensed text. If the exact number matters for your Statement of Applicability, count it in your own copy rather than trusting any blog post, including this one.
If you are coming from ISO 27001, most of 42001 will feel familiar. Three parts will not.
One small oddity, for anyone reading the text closely: the definition of statement of applicability at 3.26 cross-references "controls (3.23)", but 3.23 is information security. The intended reference is 3.21. It is an editorial slip, not a trap, but it tells you something useful about how new this document still is.
ISO does not certify anyone. Certification is issued by a certification body (CB), and the CB's own credibility comes from accreditation by a national accreditation body — ANAB in the US, UKAS in the UK, RvA in the Netherlands, DAkkS in Germany, and their equivalents elsewhere, all recognised through the IAF Multilateral Recognition Arrangement.
The scheme rules for AI specifically now sit in ISO/IEC 42006:2025, which specifies requirements for bodies providing audit and certification of artificial intelligence management systems. It governs auditor competence and audit-duration calculation, which is the practical difference between a serious audit and a rubber stamp. Accreditation bodies including ANAB, UKAS and RvA have been building their 42006-based schemes through 2025 and into 2026, and the resulting competence floor may constrain how many audits bodies can deliver in the second half of 2026 — plan lead times accordingly.
Three questions to ask any CB before you sign, and any vendor who hands you a certificate:
On adoption: public trackers put the number of certified organisations somewhere between roughly 100 in early 2026 and a few hundred by mid-2026, including several large cloud and consulting firms. Treat those figures as directional. There is no authoritative global register, the counts come from vendor-maintained lists, and they disagree with each other.
Here is the claim you will see repeatedly, and it is false: get ISO 42001 certified and you are covered for the EU AI Act.
Under the AI Act, presumption of conformity attaches only to harmonised European standards whose references have been published in the Official Journal of the European Union. ISO/IEC 42001 is an international standard, not a harmonised European one. The harmonised standards for the AI Act are being developed by CEN and CENELEC through JTC 21, with the first expected to be published in 2026, after which the Commission begins its review of whether the references can be cited in the Official Journal.
And CEN-CENELEC specifically declined to adopt 42001 for the job. For the Article 17 quality management system requirement, JTC 21 found that ISO/IEC 42001's goals and definitions were not aligned with the AI Act's requirement, and wrote a bespoke European standard, prEN 18286, instead of adopting 42001 directly. As of mid-2026, no AI Act harmonised standard had yet been cited in the Official Journal.
The timeline also moved. The Digital Omnibus on AI, proposed by the Commission in November 2025, was adopted by Parliament on 16 June 2026 and by Council on 29 June 2026, entering into force in July 2026. The revised sequence: Article 50 transparency obligations apply from 2 August 2026 (with Article 50(2) not applying to systems already on the market at that date); Article 50(2) for legacy systems and the new prohibited practices apply from 2 December 2026; high-risk obligations for stand-alone Annex III systems apply from 2 December 2027; and high-risk obligations for Annex I embedded systems from 2 August 2028.
So what is 42001 good for, regulation-wise? Real but indirect value. An AIMS gives you the organisational machinery — risk assessment, impact assessment, lifecycle records, supplier controls, post-market monitoring — that the Act's high-risk obligations will demand evidence of. You will be reusing the artefacts. You will not be presuming conformity. Anyone selling you the latter is selling you something they cannot deliver.
Certification is worth it if one of these is true: you sell AI-enabled products into enterprise or public sector procurement and security questionnaires are already asking about AI governance; you operate in a regulated sector where an auditable governance trail is the price of entry; or you have enough AI activity across enough teams that nobody can currently answer what AI are we running and who owns it.
It is probably premature if your AI footprint is a handful of vendor tools and no in-house development, or if you have no ISMS or equivalent to build on. In that case, do the inventory, do a couple of impact assessments on your highest-exposure use cases, and revisit.
Being straight about what is unresolved:
Article details
Author
Syed Bashar Ahmed
Role
AI Solution Architect
Category
Governance
Published
July 29, 2026
Read time
9 min
Syed Bashar Ahmed
AI Solution Architect
Syed Bashar Ahmed builds and ships production systems at Icybee — this piece comes out of that work, not a content calendar.
Tell us your challenge. An engineer gets back to you within 24 hours.